| # Use an official Python runtime as a parent image | |
| FROM python:3.11-slim | |
| # Set environment variables | |
| ENV PYTHONDONTWRITEBYTECODE=1 | |
| ENV PYTHONUNBUFFERED=1 | |
| ENV PORT=7860 | |
| # Set the working directory in the container | |
| WORKDIR /app | |
| # Install system dependencies (required for some Python packages and health checks) | |
| RUN apt-get update && apt-get install -y --no-install-recommends \ | |
| build-essential \ | |
| curl \ | |
| && rm -rf /var/lib/apt/lists/* | |
| # Copy the requirements file into the container | |
| COPY requirements.txt . | |
| # Install any needed packages specified in requirements.txt | |
| RUN pip install --no-cache-dir -r requirements.txt | |
| # Copy the rest of the application code | |
| COPY . . | |
| # Create a non-root user and switch to it for security | |
| RUN useradd -m appuser && chown -R appuser /app | |
| USER appuser | |
| # Expose the port the app runs on | |
| EXPOSE 7860 | |
| # Run the app using Gunicorn | |
| # Using gunicorn as the entry point for production stability | |
| CMD ["gunicorn", "--bind", "0.0.0.0:7860", "--workers", "1", "--threads", "8", "--timeout", "0", "app:server"] | |